CVE-2026-54335Low· 3.7▾ SunlitPrototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__
▾ Sunlit zone — Low / medium · no exploitation signal
impact 20.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.4%
The _.merge(target, source) utility exported by @feathersjs/commons recursively merges source into target by iterating Object.keys(source). When source was produced by JSON.parse and contains a __proto__ (or constructor / prototype) key, that key is returned as an own-enumerable property. The recursive merge then resolves target['__proto__'] to Object.prototype and writes the attacker-supplied properties onto it, polluting the prototype for all plain objects in the process for the lifetime of the Node process.
Scope of real-world risk is limited. No first-party Feathers package routes input — trusted or untrusted — through commons._.merge. The @feathersjs/authentication package, which does merge request-influenced data, uses lodash/merge (prototype-pollution-safe since 4.17.12), not this utility. Exploitation therefore requires a downstream plugin or application to pass JSON-parsed, attacker-controlled input directly through the exported _.merge.
Fixed in @feathersjs/[email protected]. The fix skips __proto__, constructor, and prototype keys during iteration — the standard remediation used by lodash and others.
Avoid passing JSON-parsed untrusted input through commons._.merge. Freezing Object.prototype or validating/sanitizing keys upstream also mitigates.
Reported responsibly by Andrew Ridings (@ridingsa).
@feathersjs/commons <= 5.0.44Upgrade to a patched release:
@feathersjs/commons 5.0.45Connected by shared product, vendor, weakness, or advisory.
CVE-2026-61534Critical· 9.1Yayson is a library for serializing and reading JSON API data in JavaScript
CVE-2026-86078Medium· 6.5n8n is an open source workflow automation platform
CVE-2026-84367Low· 3.7joi is a schema description language and data validator for JavaScript
CVE-2026-84368Low· 3.7joi is a schema description language and data validator for JavaScript
CVE-2026-85063Medium· 6.5node-csv is a full-featured CSV parser with a simple API that is tested against large datasets
CVE-2026-63376High· 8.2toml-node is a TOML parser for Node.js and the browser